Access to requested resource is denied 403 SP-API AMAZON - C#

Viewed 11902
6 Answers

I had the same error, and after days of struggle I found my solution, hope it helps somebody else.

I followed every single step in the Selling Partner API Developer Guide, but, when creating the app in the Amazon Seller Central, I used the User ARN. This was my mistake. To solve the problem I created a new app using the Rol ARN instead of the User ARN.

Like this: enter image description here

It looks like the guidance on the docs around adding a role doesnt seem to work (or I have messed it up somehow). The work around is to add the policy directly the user as per phamanh195 suggestion:

IAM Management Console => users => select user => add inline policy => click on JSON tab => add the following:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "execute-api:Invoke",
"Resource": "arn:aws:execute-api:::*"
}
]
}

Appreciate it is not best practices, but i've got access now.

p.s. i have removed the policy and it has defaulted back to the authorization error above.

Refer below issue reported on github : https://github.com/amzn/selling-partner-api-docs/issues/38

Apart from the mentioned answers above, what worked for me was to make sure that the requests were targeting the correct region. The application was created in NA and I was initially targeting EU, which gave me unauthorised access.

You must check the following headers, this error can occur due to the incorrect value from any of them.

  1. In headers you need to send x-amz-access-token i.e valid for only one-hour post generation through token API.
  2. You also have to pass the Authorization in headers this will auto-generate in postman if you choose AWS Signature type in Authorization and set the following keys(Access Key, Secret Key, Aws Region, and Service Name).

Also to test sandbox get orders API: URL value should be this https://sandbox.sellingpartnerapi-eu.amazon.com/orders/v0/orders?CreatedAfter=TEST_CASE_200&MarketplaceIds=XXXX

Sandbox API will only work as per the provided sandbox behavior.

Just throwing this out there, I got that error so many times and I made 100% sure everything was correct and in the end it was simply that I was using a post instead of a get. Tired eyes but I finally caught it and it worked.

I had the same issue and tried all solutions I could find online. In the end, it turned out to be an issue with the region. I was trying to access Amazon UK data, but calling the us-east-1 region.

Conveniently, the guide fails to mention that the actual URL has to change to accommodate any other market other than US...

Rather than using https://sellingpartnerapi-na.amazon.com as per the docs, you will need to use https://sellingpartnerapi-eu.amazon.com or whichever is your locale. You then also need to change the region in your authorization header. For me it was eu-west-1.

Related